CVE-2026-47491
Awaiting Analysis Awaiting Analysis - Queue

NVIDIA GPU Display Driver Memory Release Vulnerability

Vulnerability report for CVE-2026-47491, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: NVIDIA Corporation

Description

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user can cause improper release of memory resources, leaving a mapping accessible after the underlying memory is reused. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
nvidia gpu_display_driver *-*
nvidia gpu_display_driver *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-404 The product does not release or incorrectly releases a resource before it is made available for re-use.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in NVIDIA GPU Display Driver for Linux allows an unprivileged user to improperly release memory resources, leaving a memory mapping accessible after the original memory is reused. This could lead to various malicious outcomes such as code execution, denial of service, privilege escalation, information disclosure, or data tampering.

Detection Guidance

Detection of this vulnerability requires checking for unpatched NVIDIA GPU Display Driver versions on Linux systems. Inspect installed driver versions using commands like 'nvidia-smi' or 'dkms status'. Compare against the latest patched version from NVIDIA's official site. Monitor system logs for memory mapping errors or crashes that may indicate exploitation attempts.

Impact Analysis

If exploited, this vulnerability could allow attackers to execute arbitrary code, crash the system, gain higher privileges, steal sensitive information, or alter data on your system. Since it affects the GPU driver, it may impact graphics-intensive applications and overall system stability.

Compliance Impact

This vulnerability could lead to information disclosure and data tampering, which may violate GDPR's data protection requirements and HIPAA's safeguards for protected health information. Unauthorized access or modification of data could result in non-compliance with these regulations.

Mitigation Strategies

Update the NVIDIA GPU Display Driver for Linux to the latest patched version immediately. Monitor NVIDIA's security advisories for updates and apply them as soon as available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-47491. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart